
from xalgorix627
Designs and documents a ransomware-resilient backup architecture (3-2-1-1-0), immutability, credential isolation and automated restore testing aligned to RPO/RT
Provides a practical, security-focused playbook for implementing ransomware-resilient backups. The skill walks through asset classification, 3-2-1-1-0 architecture, immutable storage configuration, backup credential isolation, and automated restore verification.
Use when designing or auditing backup systems for ransomware resilience, meeting cyber-insurance requirements, migrating to immutable storage (S3 Object Lock, Veeam Hardened Repo), or establishing automated restore testing. Not a replacement for full IR planning.
Best for security engineering assistants and SREs (agents that can output runbooks, bash/aws/az commands and remediation checklists such as Copilot/GitHub Copilot or security-oriented Claude models).
Advisory skill for designing ransomware-resilient backup architecture following the 3-2-1-1-0 methodology. No scripts to execute — purely instructional SKILL.md with well-structured sections covering asset classification, immutable storage configuration (Veeam, AWS S3, Azure), credential isolation, and automated restore testing. Security is excellent: no dangerous commands, no credentials, no network calls to suspicious hosts. Code quality is good with clear steps and practical snippets, though some configuration examples lack error handling. Architecture follows the skill spec well with complete frontmatter and progressive disclosure.
Well-crafted cybersecurity advisory skill. Includes NIST AI RMF and CSF references in frontmatter. The 'Common Misconfigurations & Verification' section is particularly valuable — covers real-world failure modes like S3 Object Lock in Governance mode vs Compliance mode. No security concerns whatsoever.
Building Threat Hunt Hypothesis Framework
Framework and workflow to turn threat intelligence and telemetry into testable, falsifiable threat-hunting hypotheses for proactive detection.
Performing SSL/TLS Security Assessment
Use sslyze to assess SSL/TLS server configurations: supported protocols, cipher suites, certificate chains, HSTS/OCSP, and common vulnerabilities like Heartblee
Pentesting rsync (port 873)
Procedures and checks to enumerate and exploit rsync daemon modules (port 873), detect unauthenticated shares, brute-force auth, and safely verify read/write ex
Configuring Identity-Aware Proxy (IAP) for Google Cloud
Step-by-step guide to secure Google Cloud services (Compute, App Engine, Cloud Run, GKE) with Identity-Aware Proxy, access levels, and programmatic service-acco
Deception-Based Detection with Canarytoken
Create, deploy, and monitor Thinkst Canary Tokens (web, DNS, document, AWS key) to detect lateral movement and credential misuse.